Skip to content

New Malware Wave Targets Apple Devices, Challenging Security Reputation

Apple users worldwide targeted by FrigidStealer malware. Cybercrime group EvilCorp linked to the campaign, challenging the long-standing reputation of Apple devices for immunity.

This is a picture of a screen , where there are some icons , and there is a popup message on it.
This is a picture of a screen , where there are some icons , and there is a popup message on it.

New Malware Wave Targets Apple Devices, Challenging Security Reputation

Cybersecurity researchers have uncovered a new wave of malware attacks targeting Apple devices, challenging their long-standing reputation for immunity. The FrigidStealer campaign, first spotted in 2025, has been linked to the notorious cybercrime syndicate EvilCorp through its association with the threat actor group TA569.

The FrigidStealer malware is distributed through deceptive browser updates, targeting Mac users worldwide. Despite extensive searches, the specific group behind this news is unidentified. However, it is known that TA569, EvilCorp's cybercrime arm, has been using similar tactics since 2022. TA569 primarily gains access to networks through malvertising and deploys FakeUpdates/SocGholish to trick targets into downloading malware.

In 2023, multiple copycat groups emerged, employing similar web inject and traffic redirection techniques to deliver malware. Two new threat actor groups, TA2726 and TA2727, linked to TA569, have been revealed by Proofpoint. These groups act as traffic distribution services, providing support for TA569's campaigns. Recent observations show TA2727 delivering FrigidStealer alongside malware for Windows and Android hosts.

The FrigidStealer campaign marks a significant shift in cyber threats, targeting Mac users globally. While the specific group behind this news remains unknown, its links to EvilCorp through TA569 are clear. As Apple devices face increasing threats, users are urged to remain vigilant and keep their software up to date. Cybersecurity researchers continue to monitor the situation, with Proofpoint leading the way in uncovering new threat actor groups and their activities.

Read also:

Latest